VDB
KO
HIGH 8.1

GHSA-4v2w-h9jm-mqjg

Prototype Pollution in systeminformation

Details

### Impact command injection vulnerability by prototype pollution

### Patches Problem was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. Please upgrade to version >= 4.30.2

### Workarounds If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()

### For more information If you have any questions or comments about this advisory:

* Open an issue in [systeminformation](https://github.com/sebhildebrandt/systeminformation/issues/new?template=bug_report.md)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / systeminformation
Introduced in: 0 Fixed in: 4.30.5
Fix npm install systeminformation@4.30.5

References